PT-2023-11537 · Mpv+1 · Mpv+1

3Kyo0

·

Published

2020-11-24

·

Updated

2023-03-12

·

CVE-2020-19824

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MPV version 0.29.1
Description The issue allows attackers to execute arbitrary code and crash the program via the ao c parameter.
Recommendations For MPV version 0.29.1, update to version 0.30 to resolve the issue. As a temporary workaround, consider restricting the use of the ao c parameter until the update is applied.

Exploit

Fix

Race Condition

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3404
CVE-2020-19824
DLA-3358-1

Affected Products

Alt Linux
Mpv